NAVANEM

Documented vulnerability advisories

Every entry documented: technical breakdown, impact, mitigation and detection, with severity, CVSS and exploitation status at a glance.

124advisories
75critical
95exploited in the wild

124 advisories

Microsoft Windows CLFS, use-after-free elevation of privilege
CVE-2025-32701· May 13, 2025high

Microsoft Windows CLFS, use-after-free elevation of privilege

A use-after-free in the Windows Common Log File System (CLFS) driver allows an authorized local attacker to elevate privileges to SYSTEM. The driver references a kernel object after it has been freed, and an attacker who controls the reallocated memory can execute code in kernel mode. Microsoft confirmed in-the-wild exploitation as a zero-day, and CISA added the CVE to the Known Exploited Vulnerabilities catalog on the disclosure date.

Fortinet FortiVoice and multiple products, unauthenticated stack-based buffer overflow remote code execution
CVE-2025-32756· May 13, 2025critical

Fortinet FortiVoice and multiple products, unauthenticated stack-based buffer overflow remote code execution

A stack-based buffer overflow vulnerability in multiple Fortinet products, including FortiVoice, FortiMail, FortiNDR, FortiRecorder and FortiCamera, allows a remote, unauthenticated attacker to execute arbitrary code or commands by sending HTTP requests with a specially crafted hash cookie. The flaw requires no authentication and no user interaction. Fortinet confirmed exploitation in the wild against FortiVoice systems.

SAP NetWeaver Visual Composer, unauthenticated arbitrary file upload
CVE-2025-31324· Apr 24, 2025critical

SAP NetWeaver Visual Composer, unauthenticated arbitrary file upload

The SAP NetWeaver Visual Composer Metadata Uploader is not protected with proper authorization, allowing an unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. The vulnerability is an unrestricted upload of a file with a dangerous type. Successful exploitation enables an attacker to compromise the confidentiality, integrity, and availability of the affected system.

Erlang/OTP SSH server, unauthenticated pre-auth message-handling RCE
CVE-2025-32433· Apr 16, 2025critical

Erlang/OTP SSH server, unauthenticated pre-auth message-handling RCE

A flaw in the Erlang/OTP SSH server's handling of protocol messages allows an unauthenticated remote attacker to perform arbitrary code execution. By sending connection-protocol messages before authentication completes, a malicious actor can cause the SSH daemon to process them as if authenticated, gaining unauthorized access and executing arbitrary commands without valid credentials. Versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20 are affected; the issue is fixed in those releases.

Microsoft Windows CLFS, use-after-free elevation of privilege zero-day (CLFS EoP)
CVE-2025-29824· Apr 8, 2025high

Microsoft Windows CLFS, use-after-free elevation of privilege zero-day (CLFS EoP)

A use-after-free vulnerability in the Microsoft Windows Common Log File System (CLFS) Driver allows an authorized, local attacker to elevate privileges. By exploiting the freed-memory condition in the kernel-mode driver, a low-privileged user can execute code with SYSTEM-level privileges. Microsoft disclosed the flaw as an actively exploited zero-day in its April 2025 security updates.

Ivanti Connect Secure, stack-based buffer overflow pre-auth RCE
CVE-2025-22457· Apr 3, 2025critical

Ivanti Connect Secure, stack-based buffer overflow pre-auth RCE

A stack-based buffer overflow in Ivanti Connect Secure (before 22.7R2.6), Ivanti Policy Secure (before 22.7R1.4), and Ivanti ZTA Gateways (before 22.8R2.2) allows a remote, unauthenticated attacker to execute arbitrary code. The vulnerability results from an out-of-bounds write condition. Successful exploitation leads to remote code execution on the affected appliance.

Google Chrome Mojo IPC Sandbox Escape (Operation ForumTroll)
CVE-2025-2783· Mar 26, 2025high

Google Chrome Mojo IPC Sandbox Escape (Operation ForumTroll)

An incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. The flaw stems from a logical error at the boundary between the Chrome sandbox and the Windows operating system, where a confusion over handle ownership lets a compromised renderer break out of the browser sandbox without any memory-corruption primitive. Google confirmed it is aware of reports that an exploit exists in the wild.

Kubernetes Ingress-NGINX admission controller, unauthenticated RCE (IngressNightmare)
CVE-2025-1974· Mar 25, 2025critical

Kubernetes Ingress-NGINX admission controller, unauthenticated RCE (IngressNightmare)

A security issue in the Kubernetes ingress-nginx controller allows an unauthenticated attacker with access to the pod network to achieve arbitrary code execution in the context of the ingress-nginx controller under certain conditions. Because the admission controller accepts and processes attacker-supplied configuration via its admission webhook without proper authentication boundaries, a malicious AdmissionReview payload can inject NGINX configuration that is loaded by the controller. Successful exploitation can lead to disclosure of Secrets accessible to the controller, which in a default installation can read all Secrets cluster-wide.

Veeam Backup & Replication, .NET deserialization remote code execution
CVE-2025-23120· Mar 20, 2025high

Veeam Backup & Replication, .NET deserialization remote code execution

A deserialization of untrusted data vulnerability in Veeam Backup & Replication allows a remote, authenticated domain user to execute arbitrary code on the Backup Server. The flaw stems from insecure handling of .NET serialized objects in the product's internal communication, where deserialization gadget chains can be abused to run attacker-controlled code in the context of the Veeam service. Only domain-joined backup servers are affected, but exploitation requires only low-privileged domain credentials, which is a configuration explicitly discouraged by Veeam best practices yet commonly found in production.

Microsoft Windows NTFS, heap-based buffer overflow remote code execution
CVE-2025-24993· Mar 11, 2025high

Microsoft Windows NTFS, heap-based buffer overflow remote code execution

A heap-based buffer overflow in the Windows NTFS file-system driver allows an unauthorized attacker to execute arbitrary code locally. Exploitation requires that a local user mount a specially crafted Virtual Hard Disk (VHD), which triggers the overflow during file-system parsing. Microsoft confirmed the flaw was exploited in the wild as a zero-day, and CISA added it to the Known Exploited Vulnerabilities catalog on the day it was disclosed.

Apple WebKit, sandbox escape via malicious web content (zero-day)
CVE-2025-24201· Mar 11, 2025high

Apple WebKit, sandbox escape via malicious web content (zero-day)

An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. Maliciously crafted web content may be able to break out of Web Content sandbox.

Apache Tomcat Default Servlet, partial PUT path-equivalence RCE (Internal Dot)
CVE-2025-24813· Mar 10, 2025critical

Apache Tomcat Default Servlet, partial PUT path-equivalence RCE (Internal Dot)

A path equivalence flaw ('file.Name', internal dot) in Apache Tomcat's write-enabled Default Servlet allows attackers to view or inject content into security-sensitive files and, when file-based session persistence is combined with a deserialization-capable library on the classpath, to achieve remote code execution. The condition is reached by abusing Tomcat's partial PUT handling, which writes uploaded fragments to a temporary file whose name is derived from the request path. Apache Tomcat 9.0.0.M1 through 9.0.98, 10.1.0-M1 through 10.1.34, and 11.0.0-M1 through 11.0.2 are affected (EOL 8.5.0 through 8.5.100 are also known to be affected).

VMware ESXi and Workstation, TOCTOU out-of-bounds write to VMX RCE (ESXi VMX Sandbox Escape)
CVE-2025-22224· Mar 4, 2025high

VMware ESXi and Workstation, TOCTOU out-of-bounds write to VMX RCE (ESXi VMX Sandbox Escape)

VMware ESXi and Workstation contain a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a guest virtual machine can exploit the flaw to execute code as the virtual machine's VMX process running on the host. This constitutes a virtual machine sandbox escape from guest to hypervisor host.

Palo Alto Networks PAN-OS, management web interface authentication bypass
CVE-2025-0108· Feb 12, 2025critical

Palo Alto Networks PAN-OS, management web interface authentication bypass

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. Cloud NGFW and Prisma Access are unaffected.

SonicWall SMA1000, pre-authentication deserialization RCE
CVE-2025-23006· Jan 23, 2025critical

SonicWall SMA1000, pre-authentication deserialization RCE

A pre-authentication deserialization of untrusted data vulnerability in the SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) could, under specific conditions, allow a remote, unauthenticated attacker to execute arbitrary OS commands. The vulnerability arises from unsafe deserialization of attacker-controlled data. Successful exploitation results in arbitrary operating-system command execution on the appliance.

Microsoft Windows OLE, remote code execution via Outlook email
CVE-2025-21298· Jan 14, 2025critical

Microsoft Windows OLE, remote code execution via Outlook email

Windows OLE Remote Code Execution Vulnerability.

Windows Hyper-V NT Kernel Integration VSP, elevation of privilege zero-day
CVE-2025-21333· Jan 14, 2025high

Windows Hyper-V NT Kernel Integration VSP, elevation of privilege zero-day

Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability.

Ivanti Connect Secure / Policy Secure / ZTA, stack buffer overflow pre-auth RCE
CVE-2025-0282· Jan 8, 2025critical

Ivanti Connect Secure / Policy Secure / ZTA, stack buffer overflow pre-auth RCE

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Windows Common Log File System Driver, elevation of privilege
CVE-2024-49138· Dec 10, 2024high

Windows Common Log File System Driver, elevation of privilege

Windows Common Log File System Driver Elevation of Privilege Vulnerability.

Windows LDAP, denial of service (LDAPNightmare)
CVE-2024-49113· Dec 10, 2024high

Windows LDAP, denial of service (LDAPNightmare)

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability.

show